CVE-2026-59310
vCenter Syslog server directory traversal -> arbitrary code execution (CVSS 9.8)
- Severity
- critical
- Affected product
- VMware vCenter Server
- Affected versions
- VMware vCenter Server all versions before the fix
- CISA KEV
- Listed as a known exploited vulnerability
- EPSS
- 1% chance of exploitation in the next 30 days
- Added to NewScan
- 2026-08-19
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the VMware vCenter Server appliance and reports this CVE when the detected version falls inside the affected range below.
Added 2026-08-19 from CISA KEV. A malicious actor with network access to vCenter writes outside the intended directory through the Syslog service and reaches code execution. No `lt`: this row's fingerprint is body markers on /ui/ and /websso/SAML2/SSO and vCenter publishes no version to an anonymous caller, so the row stays an advisory observation on a confirmed vCenter rather than a version match. Patch to the build VMware names in the advisory and keep 514/1514 off untrusted networks.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →